# Limits and rate limits

> Request rate limits, body and document sizes, search pages, webhook limits and token lifetimes.

Source: https://developers.anpheros.com/guides/limits

| Limit | Value | Notes |
|---|---|---|
| Requests per credential | 600 / minute (per key; configurable per key) | shared across all instances; `Retry-After` on 429 |
| Requests per IP | 600 / minute | per instance |
| JSON body | 2 MiB | refused from `Content-Length` before reading |
| Document upload | 25 MiB | direct-to-storage or through the platform |
| Resource nesting | 64 levels | |
| Text field length | 10 000 characters | |
| Search page | `_count` ≤ 200 | `_revinclude` returns at most 1 000 |
| Webhook endpoints | 10 per project and environment | |
| Webhook attempts | 10 with exponential backoff (30 s → 1 h) | endpoint auto-disabled after 10 consecutive failures |
| Idempotency keys | 128 characters, kept 24 h | |
| Access token / refresh token / auth code | 30 min / 30 days / 10 min | |
| Consent duration | 30, 90, 180 or 365 days | |

## Sandbox (self-service)

| Limit | Value | Notes |
|---|---|---|
| Resource writes | 10 000 per project per day (UTC) | every created, updated or deleted resource counts (a bundle of 200 entries is 200); 429 with `Retry-After` until midnight UTC; the synthetic patients and their reset do not count |
| Patients | 500 per project, besides its 30 synthetic patients | |
| Documents | 250 MB per project | |
| Organisations | 3 created per account | |
| Sandbox projects | 5 per organisation | |
| API keys | 20 active per project | |

Production projects have none of the sandbox limits; they are open to verified organisations with a
signed data processing agreement, and their allowances come from the plan: see [Pricing](https://developers.anpheros.com/guides/pricing). The
sandbox is free, and the first month of production is free.
